Page MenuHomeMiraheze

Wiki Requesters are being changed to "Hearth to matilda"
Closed, ResolvedPublic

Description

Many new wiki requests have Hearth to matilda listed as their requester. This should not be possible.
https://meta.miraheze.org/wiki/Special:RequestWikiQueue?requester=Hearth+to+matilda

Event Timeline

Void triaged this task as High priority.Jan 3 2019, 22:55
Void created this task.
Void added a comment.Jan 3 2019, 22:59

This issue seems to affect all users created after Hearth to matilda was added to meta.

Yikes! Appears to possibly be a hijacking/compromised account issue. Although I’m familiar with session hijacking from an IT perspective, without technical data from the server logs (which I know can’t be shared) I can’t comment further.

I would recommend perhaps temporarily disabling wiki requests (i.e. remove “requestwiki” from the “user” group on Meta) and add a sitenotice to that effect.

Void added a comment.Jan 3 2019, 23:06

I doubt there's any compromising going on here, otherwise this would be a security task. The original requester is still visible in the farmer log, so that does help.

Paladox raised the priority of this task from High to Unbreak Now!.Jan 3 2019, 23:23

This means effectively RequestWiki is broken.

(though it works for me, but someone requested a wiki after me and had this name)

Void claimed this task.Jan 3 2019, 23:30

cw_user was using a SMALLINT, which has a max size of 32767

Void closed this task as Resolved.Jan 3 2019, 23:31